This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hacked By Redwood Broker & Coharts

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First thanks in advance for any help! It's very much appreciated. I'm a computer novice and very thankful to find this forum and very thankful for any help I can get.
I have Pest Patrol, Spybot Search and Destroy, Adaware 6.0, Trojan Remover and Sygate Personal Firewall installed on my computer. (Though I did the best I can, I honestly don't quite grasp all the functions with setting up the Sygate Firewall for maximum security and would appreciate any tips on that. None of my protection software (which I update regularly) currently shows I have any problems though I do occasionally get pop-ups from Sygate and am often not sure whether to accept of deny the action. I ran Sygates security test and it showed I have a number of ports open, but I have no idea how to get them closed.
Problems:
1.) My Documents folder loads at boot-up (no big problem, but minor irritation).
2.) There is something called Redwood Broker loaded somewhere on my computer. I read this is used by 'elite' hacks and installs a MSSQL Server and it's own firewall on my computer to disguise itself from detection by my firewall and anti sypware/trojan software and take over.
3.) An ace of diamonds appears in my Control Panel (I believe it's Trojan.WinReboot) I tried to get rid of it and quit having problems rebooting, but the icon is still there.
4.) I am in East Europe and working through a local internet cable server (which I don't trust).

Here is my
Logfile of HijackThis:
v1.97.7
Scan saved at 4:05:18 PM, on 2/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\WINDOWS\System32\TFNF5.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\Program Files\PestPatrol\PPControl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Scrub XP\ScrubXP\scrubxp.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\DOCUME~1\soho3504\LOCALS~1\Temp\$wc0\HIJACK~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\userinit.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TosHKCW.exe] C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 01
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [sc] C:\Program Files\Scrub XP\ScrubXP\scrubxp.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [Spamihilator] "C:\Program Files\Spamihilator\spamihilator.exe"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .hlq: C:\Program Files\Internet Explorer\PLUGINS\nphcd32.dll
O12 - Plugin for .mng: c:\program files\internet explorer\PLUGINS\NpHcd32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab


Thanks again for any and all help anyone can offer. All the Best!!
Armadillo Pete
For the future:- —————– Important: Create a folder on the C: drive called C:\HJT. You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary. Delete the old copy please. —————– I can not see anything running in your log that I would class as malware, all looks clean.
Hi Pete I agree with ChrisRLG - no obvious problem in your log. The only suspicious line is the F2 entry: F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\userinit.exe - could you please open C:\Windows\system.ini in Notepad and post the content here.
Thank you Chris and FBJ, Your responses are much appreciated. Please forgive my computer ignorance. I copied HJT to the folder as you suggested ran Scan but when I hit fixed this it says nothing selected and the log disappears. Am I suppossed to check everything when I click fixed this? Any suggestions of how to stop My Documents folder from loading on boot or how to get rid of the Ace of Diamonds Icon (with gibberish underneath) from my control panel. connected to the Korean Trojan I mentioned. Maybe it's nothing, but when I previously ran regcleaner on my computer I saw Redwood Broker in the registry and when looking around trying to find out what it was I found different info about RTC's and RAT's listing Redwood Broker as a Remote Access Trojan Horse that gets through port 3001. Example: (www.comodon.com) (threats to your security section). God bless and thanks so much for taking the time to help. Pete ; for 16-bit app support [drivers] wave=mmdrv.dll timer=timer.drv [mci] [driver32] [386enh] woafont=app850.FON EGA80WOA.FON=EGA80850.FON EGA40WOA.FON=EGA40850.FON CGA80WOA.FON=CGA80850.FON CGA40WOA.FON=CGA40850.FON [Routing.Information] DebuggingFlags=1075817103
That does not look a problem either. We were not advising you fix anything with hijackthis as nothing it found was wrong. The control panel item you should find in c:\windows\system32 with a xxx.cpl extension to the file name. Change to xxx.old, reboot and see if that makes it disappear. If so delete that file.
Thanks again! You got my ace in the hole out of the wrong hole. As you didn't mention it, I assume Redwood Broker isn't an RCTH or anything to worry about? Your forum is fantastic. All the best and happy trails!
Glad we could help :D

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI